✅ Feature availability: You can use the Vanta Agent when AI is enabled on a current plan. The specific agent capabilities available depend on your plan, enabled features, and user permissions.
The Vanta Agent can help you find and capture screenshot-based evidence for your document tests. The agent reads the evidence description for a document and determines what to collect. Then it navigates the relevant app, captures audit-ready screenshots, and checks that they meet the requirement before returning them for you to review.
⚙️ User permissions: Admins, Editors, and Audit Limited Editors can upload evidence across all documents. Collaborators can upload evidence for documents where they’re assigned as Document Owner. Learn more: User Permissions by Product Area
Document eligibility
The Vanta Agent can collect screenshot-based evidence for document tests where the evidence lives in a web page or web-based app—things like a configuration screen, dashboard, admin panel, or public web page, whether it's publicly accessible or behind a login.
If the agent determines it can't collect evidence for a document, it will let you know—some document tests require evidence you write or upload yourself, like a policy, a signed agreement, or documentation of a process.
This feature isn't available for restricted documents or if you're using Vanta for Government accounts.
Using read-only service accounts
For security purposes, we recommend creating dedicated, read-only service accounts for the Vanta Agent to use during evidence collection when authentication is needed.
This ensures the agent only has the minimal access needed to navigate your apps and capture screenshots, without exposing your primary credentials.
When the agent hits a login wall, it pauses to ask you to enter credentials in the live browser view. Use your service account credentials to log in.
Use a regular username and password, MFA (text or code), or SSO to log in. Biometric login (like TouchID) and hardware security keys aren't supported, since the agent uses a remote browser that can't access your device's hardware.
The agent remembers your login for up to 3 days. If you've already authenticated during a previous evidence collection session, you won't need to log in again until that session expires or the third-party app requires re-authentication.
The agent operates in read-only mode—it will never create, modify, or delete anything in your apps. It only navigates and captures screenshots.
Collecting screenshot evidence
To collect screenshot evidence, you'll need to authenticate into the relevant apps if prompted, then review and approve the screenshots the agent captured before they're uploaded to the document.
To collect screenshot evidence with the Vanta Agent:
Open the Vanta Agent and enter a prompt describing the evidence you need.
Log in to the relevant apps if prompted.
Monitor the agent's progress in the live browser view as it navigates and captures screenshots.
Review the screenshots the agent captured and approve them before they're uploaded to the document—your explicit approval is required.
ℹ️ Note: Screenshot collection was previously available from a Collect a screenshot button within eligible documents. That experience was replaced by the flow described above.
Example prompts
Collect a screenshot showing MFA is enabled for our AWS root account
Find my company’s privacy policy from https://trust.vanta.com/ and upload the necessary evidence
Refresh the screenshots for our vulnerability scan evidence
Collect a screenshot of our operational alert dashboard from Datadog
Capture a screenshot of our company's status page
Chat history
Your chats are automatically saved to your Vanta Agent chat history.
If you close the chat or refresh the page during evidence collection, the agent may be interrupted mid-task.
If evidence collection is interrupted, open the chat from your chat history and ask the agent to continue, or open a new chat to start fresh.

